Position: Information Security Analyst (NQV)
Location: Norfolk Naval Shipyard 100% on-site
Clearance: Top Secret clearance
Job Description:
The Information Security Analyst (NQV) shall work to support DoD Risk Management Framework (RMF) and validate Network and System assets. They will be responsible to:
- a. Follow Accreditation & Authorization (A&A) process and standards.
- b. Perform System / network vulnerability analysis.
- c. Conduct Risk assessment and risk mitigation analysis.
- d. Perform Security Test and Evaluation (ST&E) processing.
- e. Validate Security Technical Implementation Guide (STIG) Processing. Use automated STIG processing tools [e.g., Security Content Automation Protocol (SCAP), Evaluate STIG, STIGMAN, EMASSter]. Use of Enterprise Mission Assurance Support Services (eMASS) and similar RMF repositories.
- f. Setup and execute A&A Business Rules, Standard Operating Procedures (SOP)s, Concept of Operations (CONOP)s, and Plans.
- g. Perform Contingency planning, training and testing.
- h. Establish/interrupt Firewall Policy.
- i. Identify Interrupt, register Ports & Protocols.
- j. Review Hardware / Software, network boundaries, flow diagrams and technical drawings.
- k. Identify interrupting information in the system baseline configuration in VRAM by uploading vulnerability scan of a representative baseline system.
- l. Advise on the proper method to mitigate vulnerabilities.
- m. Produce executive documents, reports, project plans and plan of action and milestones (POA&M).
Qualifications:
Minimum of seven (7) years of experience in CS/A&A analysis support in IA controls analysis, conducting risk assessments, risk mitigation analysis, or developing plans. KSAs include:
- Qualified and registered as a Navy Qualified Validator (NQV)
- Expert knowledge of and experience with CS/RMF requirements as defined by Public Laws, National, DoD, and DON [e.g., Federal Information Security Management Act (FISMA), DoDD 8100.02, DODI 8500.01, DoDI 8520, DoDI 8530, DoDI 8531, SECNAV 5239 Series and OPNAV 5239 Series, NIST Special Publications Series 800, etc.]
- Expert and Mastery levels with institutional knowledge on the mission critical procedures, systems, and processes, as they pertain to Information Technology and Cyber Security requirements.
- Experience in certifying and accrediting DON information systems and networks, as well as Platform IT.
- Expert knowledge and experience with the requirements outlined in OPNAVINST N9210.3 Safeguarding Naval Nuclear Propulsion Information
Education:
Bachelor’s degree in an IT related discipline OR Level II Certification (Security+ or better) AND a minimum of seven (7) years of experience.
Certifications:
- Active Security + CE or higher
- Active NQV